Skip to content
Threat Feed
critical advisory

Path Traversal Vulnerability in Cimetrics BACstac

An unauthenticated remote attacker can exploit a path traversal vulnerability in Cimetrics BACstac to read or overwrite arbitrary files via maliciously crafted BACnet File Object names.

CVE search metadata

CVE search record: CVE-2025-41753. Severity: critical. CVSS: 9.8. KEV: no. Product: BACstac. Brief: Path Traversal Vulnerability in Cimetrics BACstac. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2025-41753/

CVE-2025-41753 describes a critical path traversal vulnerability within the Cimetrics BACstac software. The vulnerability exists because the application interprets the object name of a dynamically created BACnet File Object as a file path without performing sufficient input validation. Because the system fails to restrict paths to the intended directory, an unauthenticated, remote attacker can supply a crafted, relative path as the object name. This behavior allows the attacker to traverse outside the designated file directory to read or overwrite arbitrary files on the underlying host system. Successful exploitation poses a risk of full system compromise, as an attacker could potentially overwrite configuration files or inject malicious binaries to achieve remote code execution. Given the critical CVSS 9.8 score and the nature of industrial control system (ICS) protocols, this vulnerability represents a significant risk to the integrity and availability of affected industrial environments.

Impact

Successful exploitation allows unauthenticated remote attackers to gain unauthorized read/write access to the file system. This can lead to the exfiltration of sensitive configuration data, the disruption of critical industrial processes through file modification, or full system takeover via remote code execution. Impact is concentrated in industrial sectors utilizing the BACstac software stack for building automation and control.

Recommendation

  • Identify all instances of Cimetrics BACstac within the environment and evaluate exposure to the network.
  • Implement strict network segmentation and firewall rules to limit access to BACnet services (UDP 47808) to trusted, authorized systems only.
  • Prioritize the application of patches or vendor-provided updates to address CVE-2025-41753 immediately upon release.
  • Monitor logs for unusual file system access attempts or unexpected modifications to configuration files on hosts running BACstac.

Immediate actions

Isolate BACnet endpoints (UDP 47808) from untrusted networks.

SOC 24h

Mitigations

Patch Cimetrics BACstac to the latest version.

immediate IT Operations

CVE-2025-41753